Return to Prove you can design and implement cloud security architecture, user and device security, network security, assurance, and more.
Protect the infrastructures that clients rely on with the Cisco Certified Network Professional (CCNP) Security certification.
To earn your certification, you’ll take a core exam and one concentration exam of your choice.
Core Exam
Implementing and Operating Cisco Security Core Technologies.
Concentration Exam
Securing Networks with Cisco Firewalls.
Includes both SPWIPF / SFWIPA.
Concentration Exam
Troubleshooting Cisco Data Center Infrastructure.
Concentration Exam
Securing Email with Cisco Email Security Appliance.
Concentration Exam
Securing the Web with Cisco Secure Web Appliance.
Concentration Exam
Implementing Secure Solutions with Virtual Private Networks.
Concentration Exam
Automating and Programming Cisco Security Solutions.
Concentration Exam
Designing and Implementing Secure Cloud Access for Users and Endpoints.
The Implementing and Operating Cisco Security Core Technologies (SCOR) Learning Path helps you gain the skills and technologies needed to implement core Cisco security solutions.
This Learning Path will ready you to provide advanced threat protection against cybersecurity attacks and prepare you for senior-level security roles.
This Learning Path prepares you for the 350-701 SCOR v1.1 exam. If passed, you earn the Cisco Certified Specialist – Security Core certification and satisfy the core exam requirement for the Cisco Certified Network Professional (CCNP) Security and Cisco Certified Internetwork Expert (CCIE) Security certifications.
Module 1: Network Security Controls Core Skills
• Network Security Technologies
• Cisco Secure Firewall ASA Deployment
• Cisco Secure Firewall Threat Defence Basics
• Cisco Secure Firewall Threat Defence IPS, Malware, and File Policies
• Cisco Secure Email Gateway Basics
• Cisco Secure Email Gateway Policy Configuration
• Cisco Secure Web Appliance Deployment.
Module 2: Endpoints and Systems Core Skills
• Common Endpoint Attacks
• Cisco Umbrella Deployment
• Endpoint Security Technologies
• Cisco Secure Endpoint.
Module 3: Identity Access Management Core Skills
• Cisco Secure Network Access Solutions
• 802.1X Authentication
• 802.1X Authentication Configuration.
Module 4: Secure Transport Core Skills
• VPN Technologies and Cryptography Concepts
• Cisco Secure Site-to-Site VPN Solutions
• Cisco IOS VTI-Based Point-to-Point IPsec VPNs
• Point-to-Point IPsec VPNs on the Cisco Secure Firewall ASA and Cisco Secure Firewall Threat Defence
• Cisco Secure Remote Access VPN Solutions
• Remote-Access SSL VPNs on the Cisco Secure Firewall ASA and Cisco Secure Firewall Threat Defence.
Module 5: Secure Network Infrastructure and Telemetry Core Skills
• Network Infrastructure Protection
• Control Plane Security Solutions
• Layer 2 Data Plane Security Controls
• Layer 3 Data Plane Security Controls
• Management Plane Security Controls
• Traffic Telemetry Methods
• Cisco Secure Network Analytics Deployment.
Module 6: Cloud Security Concepts Core Skills
• Cloud Computing and Cloud Security
• Cloud Security
• Cisco Secure Cloud Analytics Deployment
• Software-Defined Networking.
Module 7: Network Security Core Skills
• Describe Information Security Concepts
• Describe Common TCP/IP Attacks
• Describe Common Network Application Attacks.
By the end of this course, you should be able to:
Professional-level certifications expand on the foundations of associate-level certifications. They cover more advanced topics and allow candidates to hone in on a specific focus area of their choice. Many professional-level certification candidates are looking to prove they’re the best of the best in a specialised field.
Whilst there are no formal prerequisites, learners often have three to five years of experience implementing security solutions.
There are two recommended training offers to help you prepare for the 300-710 SNCF exam.
When preparing, it is recommended that you start with the Fundamentals of Cisco Firewall Threat Defense and Intrusion Prevention (SFWIPF) training, followed by the Securing Data Center Networks and VPNs with Cisco Secure Firewall Threat Defense (SFWIPA) training offering.
SPWIPF:
The Fundamentals of Cisco Firewall Threat Defense and Intrusion Prevention learning path equips you with the skills to effectively manage the Cisco Secure Firewall.
You’ll gain an understanding of Cisco Secure Firewall architecture and deployment, base configuration, packet processing and advanced options, and conducting Secure Firewall administration troubleshooting.
SPWIPA:
The Advanced Techniques for Cisco Firewall Threat Defense and Intrusion Prevention learning path shows you how to deploy Cisco Secure Firewall Threat Defense system and its features as a data center network firewall or as an Internet Edge firewall with Virtual Private Network (VPN) support.
You will learn how to configure identity-based policies, Secure Sockets Layer (SSL) decryption, remote-access VPN, and site-to-site VPN before moving on to advanced Intrusion Prevention System (IPS) configuration and event management, integrations with other systems, and advanced troubleshooting.
You will also learn how to automate configuration and operations of Cisco Secure Firewall Threat Defense system using programmability and Application Programming Interfaces (APIs) and how to migrate configuration from Cisco Secure Firewall Adaptive Security Appliances (ASA).
This learning path prepares you for the 300-710 Securing Networks with Cisco Firepower (SNCF) exam. If passed, you earn the Cisco Certified Specialist – Network Security Firepower certification and satisfy the concentration exam requirement for the Cisco Certified Networking Professional (CCNP) Security certification.
Module 1: Cisco Secure Firewall Architecture and Deployment
• Introducing Cisco Secure Firewall Threat Defence
• Describing Cisco Secure Firewall Threat Defence Deployment Options
• Describing Cisco Secure Firewall Threat Defence Management Options.
Module 2: Cisco Secure Firewall Base Configuration
• Configuring Basic Network Settings on Cisco Secure Firewall Threat Defence
• Configuring High Availability on Cisco Secure Firewall Threat Defence
• Configuring Auto Network Address Translation on Cisco Secure Firewall Threat Defence.
Module 3: Packet Processing and Advanced Inspection
• Describing Packet Processing and Policies on Cisco Secure Firewall Threat Defence
• Configuring Discovery Policy on Cisco Secure Firewall Threat Defence
• Configuring Prefilter Policy on Cisco Secure Firewall Threat Defence
• Configuring Access Control Policy on Cisco Secure Firewall Threat Defence
• Configuring Security Intelligence on Cisco Secure Firewall Threat Defence
• Configuring File Policy on Cisco Secure Firewall Threat Defence
• Configuring Intrusion Policy on Cisco Secure Firewall Threat Defence.
Module 4: Secure Firewall Administration and Troubleshooting
• Performing Basic Threat Analysis on Cisco Secure Firewall Management Center
• Managing Cisco Secure Firewall Threat Defence System
• Troubleshooting Basic Traffic Flow
• Cisco Secure Firewall Threat Defence Device Manager.
Module 1: Cisco Secure Firewall Advanced Firewall Configurations
• Reviewing Cisco Secure Firewall Threat Defence Functionalities
• Describing Advanced Deployments on Cisco Secure Firewall Threat Defence
• Configuring Advanced Device Settings on Cisco Secure Firewall Threat Defence
• Configuring Dynamic Routing on Cisco Secure Firewall Threat Defence
• Configuring Advanced NAT on Cisco Secure Firewall Threat Defence.
Module 2: Advanced Snort Configurations and Features
• Configuring SSL Policy on Cisco Secure Firewall Threat Defence
• Deploying Identity-Based Policies on Cisco Secure Firewall Threat Defence
• Configuring Advanced Access Control Settings on Cisco Secure Firewall Threat Defence.
Module 3: Cisco Secure Firewall VPN Technologies
• Deploying Remote Access VPN on Cisco Secure Firewall Threat Defence
• Deploying Site-to-Site VPN on Cisco Secure Firewall Threat Defence.
Module 4: Cisco Secure Firewall Administration, Integration, and Troubleshooting
• Describing Advanced Event Management Cisco Secure Firewall Threat Defence
• Describing Integrations on Cisco Secure Firewall Threat Defence
• Troubleshooting Advanced Traffic Flow on Cisco Secure Firewall Threat Defence
• Automating Cisco Secure Firewall Threat Defence
• Migrating to Cisco Secure Firewall Threat Defence.
By the end of this course, you should be able to:
By the end of this course, you should be able to:
Professional-level certifications expand on the foundations of associate-level certifications. They cover more advanced topics and allow candidates to hone in on a specific focus area of their choice. Many professional-level certification candidates are looking to prove they’re the best of the best in a specialised field.
Whilst there are no formal prerequisites, learners often have three to five years of experience implementing security solutions.
The Implementing and Configuring Cisco Identity Services Engine learning path teaches you to deploy and use the Cisco Identity Services Engine (ISE), an identity and access control policy platform that simplifies the delivery of consistent, highly secure access control across wired, wireless, and VPN connections.
Completing this learning path will help you prepare for the Implementing and Configuring Cisco Identity Services Engine (300-715 SISE) exam and earn your Cisco Certified Specialist – Security Identity Management Implementation certification. Passing this exam can also fulfil the concentration exam requirement for the CCNP Security certification.
Module 1: Architecture and Deployment
• Introducing Cisco ISE Architecture
• Introducing Cisco ISE Deployment.
Module 2: ISE Policy Enforcement
• Introducing Cisco ISE Policy Enforcement Components
• Introducing Cisco ISE Policy Configuration
• Troubleshooting Cisco ISE Policy and Third-Party NAD Support
• Exploring Cisco TrustSec.
Module 3: ISE Access Management
• Web Auth and Guest Services
• Configuring Hotspots and Guest Portals
• Cisco ISE BYOD
• Working with Network Access Devices.
Module 4: ISE Profiler
• Cisco ISE Profiler
• Introducing Profiling Best Practices and Reporting.
Module 5: ISE Endpoint Compliance
• Introducing Cisco ISE Endpoint Compliance Services
• Configuring Client Posture Services and Compliance.
By the end of this course, you should be able to:
Professional-level certifications expand on the foundations of associate-level certifications. They cover more advanced topics and allow candidates to hone in on a specific focus area of their choice. Many professional-level certification candidates are looking to prove they’re the best of the best in a specialised field.
Whilst there are no formal prerequisites, learners often have three to five years of experience implementing security solutions.
The Securing Email with Cisco Email Security Appliance learning path shows you how to deploy and use Cisco® Email Security Appliance to establish protection for your email systems against phishing, business email compromise, and ransomware, and to help streamline email security policy management.
Module 1: ESA Architecture and Deployment
• Describing the Cisco Email Security Appliance
• Controlling Sender and Recipient Domains.
Module 2: ESA Policy Enforcement
• Controlling Spam with Talos SenderBase and Anti-Spam
• Using Anti-Virus and Outbreak Filters
• Using Mail Policies
• Using Content Filters
• Using Message Filters
• Preventing Data Loss.
Module 3: Message Authentication and Encryption
• Using LDAP
• Describing SMTP Session Authentication
• Using Email Authentication
• Using Email Encryption.
Module 4: ESA Administration
• Administering the Cisco Email Security Appliance
• Using System Quarantines and Delivery Methods
• Centralised Management Using Clusters
• Testing and Troubleshooting.
By the end of this course, you should be able to:
Professional-level certifications expand on the foundations of associate-level certifications. They cover more advanced topics and allow candidates to hone in on a specific focus area of their choice. Many professional-level certification candidates are looking to prove they’re the best of the best in a specialised field.
Whilst there are no formal prerequisites, learners often have three to five years of experience implementing security solutions.
The Securing the Web with Cisco Web Security Appliance learning path shows you how to implement Cisco Web Security Appliance (WSA), powered by Cisco Talos, to provide advanced protection for business email and control against web security threats.
You’ll learn how to deploy proxy services, use the solution’s anti-malware features, and more.
Module 1: Cisco WSA Architecture, Deployment, and Administration
• Cisco WSA Overview
• Proxy Services
• Cisco WSA Authentication
• Administration and Troubleshooting.
Module 2: Cisco WSA Policy Enforcement
• Decryption Policies
• Differentiated Traffic Access Policies and Identification Profiles
• Defending Against Malware
• Acceptable Use Control Settings
• Data Security and Data Loss Prevention.
By the end of this course, you should be able to:
Professional-level certifications expand on the foundations of associate-level certifications. They cover more advanced topics and allow candidates to hone in on a specific focus area of their choice. Many professional-level certification candidates are looking to prove they’re the best of the best in a specialised field.
Whilst there are no formal prerequisites, learners often have three to five years of experience implementing security solutions.
The Implementing Secure Solutions with Virtual Private Networks learning path teaches you how to implement, configure, monitor, and support enterprise virtual private network (VPN) solutions and builds the knowledge and skills necessary to deploy and troubleshoot tools for security, remote access, and increased privacy.
Completing this course will prepare you to take the Implementing Secure Solutions with Virtual Private Networks (300-730 SVPN) exam and fulfil the concentration exam requirement of the CCNP Service Provider certification.
Module 1: Site-to-Site
• Introducing VPN Technology Fundamentals
• Implementing Site-to-Site VPN Solutions
• Implementing Cisco IOS Site-to-Site FlexVPN Solutions
• Implementing Cisco IOS GET VPN Solutions.
Module 2: Remote Access VPNs
• Implementing Cisco AnyConnect VPNs
• Implementing Clientless VPNs.
By the end of this course, you should be able to:
Professional-level certifications expand on the foundations of associate-level certifications. They cover more advanced topics and allow candidates to hone in on a specific focus area of their choice. Many professional-level certification candidates are looking to prove they’re the best of the best in a specialised field.
Whilst there are no formal prerequisites, learners often have three to five years of experience implementing security solutions.
The Implementing Automation for Cisco Security Solutions learning path covers the tools and the benefits of leveraging programmability and automation in Cisco Security Solutions.
Module 1: Using APIs and Cisco devices
• Introducing Cisco Security APIs
• Consuming Cisco AMP for Endpoints APIs
• Using Cisco ISE
• Using Cisco pxGrid APIs
• Using Cisco Threat Grid APIs.
Module 2: Umbrella and APIs
• Investigating Cisco Umbrella Security Data Programmatically
• Exploring Cisco Umbrella Reporting and Enforcement APIs.
Module 3: API Operations
• Automating Security with Cisco Firepower APIs
• Operationalizing Cisco Stealthwatch and Its API Capabilities
• Using Cisco Stealthwatch Cloud APIs
• Describing Cisco Security Management Appliance APIs.
By the end of this course, you should be able to:
Professional-level certifications expand on the foundations of associate-level certifications. They cover more advanced topics and allow candidates to hone in on a specific focus area of their choice. Many professional-level certification candidates are looking to prove they’re the best of the best in a specialised field.
Whilst there are no formal prerequisites, learners often have three to five years of experience implementing security solutions.
The Designing and Implementing Secure Cloud Access for Users and Endpoints learning path will show you the skills for designing and implementing cloud security architecture, user and device security, network and cloud security, application and data security, visibility and assurance, and threat response.
Some of the Cisco solutions covered in this learning path include Cisco SecureX, Cisco XDR, Cisco Duo, Cisco ISE, Cisco Catalyst SD-WAN, Cisco Umbrella, Cisco Secure Firewall, Cisco Secure Workload, Cisco Secure Analytics, and more.
This learning path prepares you for the 300-740 SCAZT exam. If passed, you satisfy the concentration exam requirement for the Cisco Certified Network Professional (CCNP) Security certification.
Module 1: Cloud Security Architectures
• Industry Security Frameworks
• Cisco Security Reference Architecture Fundamentals
• Cisco Security Reference Architecture Common Use Cases
• Cisco SAFE Architecture.
Module 2: User and Device Authentication and Posturing
• Certificate-Based User and Device Authentication
• Cisco Duo Multifactor Authentication for Application Protection
• Cisco Duo with AnyConnect VPN for Remote Access
• Cisco ISE Endpoint Compliance Services
• SSO Using SAML or OpenID Connect.
Module 3: Control and Secure Access to Cloud Applications
• Reverse Proxy
• Cisco SD-WAN Security Content Filtering
• Cisco SD-WAN to Cisco Umbrella SIG Integration
• Cisco Umbrella Cloud Access Security Broker
• Cisco SD-WAN with ThousandEyes
• Security Policies for Remote Access VPN
• Cisco Secure Access
• Cisco Secure Firewall.
Module 4: Cloud Application and Data Security
• Web Application Firewall
• Cisco Secure Workload Deployment, Agents, and Connectors
• Cisco Secure Workload Structure and Policy
• Cloud Security Attacks and Mitigations
• Multicloud Security Policies.
Module 5: Cloud Visibility and Assurance
• Cloud Visibility and Assurance
• Cisco Secure Network Analytics and Cisco Secure Analytics and Logging
• Cisco XDR
• Cisco Attack Surface Management
• Cloud Applications and Data Access Verification.
Module 6: Responding to Threats in the Cloud
• Automation of Cloud Policy
• Response to Cloud Threats
• Automation of Cloud Threat Detection and Response.
By the end of this course, you should be able to:
Professional-level certifications expand on the foundations of associate-level certifications. They cover more advanced topics and allow candidates to hone in on a specific focus area of their choice. Many professional-level certification candidates are looking to prove they’re the best of the best in a specialised field.
Whilst there are no formal prerequisites, learners often have three to five years of experience implementing security solutions.